Introduction

Plugin dependencies for DeepSeek Harness (dsh) are managed with pnpm and layered into dsh.profile.bundles. Directly using pnpm up --latest or manually editing these dependencies can easily leave the profile in a half-finished state, break version pinning, leave layer lists out of date, or cause composition validation failures, preventing dsh from starting after a restart.

dsh-plugin-updater is designed to address these pain points. It provides a complete workflow—including backup, preservation of pinning style, reconciliation, dual validation, and real startup verification—to keep the environment usable after updating or uninstalling plugins.

What Is It?

dsh-plugin-updater is a plugin update and uninstallation tool for DeepSeek Harness (dsh). It is maintained by dp419936514. Its core value lies in safely managing third-party plugin dependencies through a “backup -> validation -> startup verification -> rollback on failure” pipeline.

Core Features

  • Plugin manifest: Displays plugin names, current versions, available upgrade versions, and marks pinned, deprecated, and local dependencies. Supports refreshing the manifest via pnpm outdated.
  • Two update modes: Supports upgrading to the latest version or upgrading within the original version constraint. Cross-major-version changes are indicated in the UI.
  • One-click operations: Select plugins on the settings page, confirm again, and then execute. Supports real-time progress and itemized “old -> new” change reports.
  • Itemized uninstallation: Each plugin row has an “Uninstall” button. The workflow includes: backup -> pnpm remove -> bundles reconciliation -> composition validation + startup verification on a temporary port. Failures are rolled back automatically.
  • Rollback mechanism: Failed operations are automatically restored; you can also manually roll back to the most recent 10 historical backups from the settings page.
  • Smart restart: Automatically detects how dsh is started (systemd user service or foreground/background process), uses the corresponding command or detached process to launch a new process, and ensures the old process exits before loading the new version.
  • Operation history: The results of each update, uninstallation, and rollback are recorded in <profile>/.dsh-plugin-updater/history.l.

Installation and Enablement

Install it in the web profile:

dsh plugin --profile web add github:dp419936514/dsh-plugin-updater

After restarting dsh web, a “Plugin Updates” section appears on the settings page. To uninstall the plugin itself, use the command line:

dsh plugin --profile web remove dsh-plugin-updater

Typical Usage

Settings Page Actions

  1. Open the “Plugin Updates” section and select the plugins to update (exact pinned plugins are not selected by default).
  2. Choose an update mode and click “Update Selected with One Click”.
  3. After success, click “Restart dsh” to apply the changes.

Command-Line Actions

  • Check manifest: node bin/dpu.mjs check
  • Update all: node bin/dpu.mjs update --yes
  • Update a specific plugin: node bin/dpu.mjs update --targets dsh-cost-meter --yes
  • Uninstall a specific plugin: node bin/dpu.mjs uninstall --targets dsh-cost-meter --yes
  • Rollback: node bin/dpu.mjs rollback
  • Restart service: node bin/dpu.mjs restart --yes

Cautions

  • Scope limitation: Manages only third-party dependencies in the profile. It does not upgrade dsh itself, modify agent presets, sessions, or credentials, or install new plugins for you.
  • Manual updates: Updates are limited to the plugins you select; there is no automatic following of new versions.
  • Built-in package protection: Updates to built-in @deepseek-ai/* packages are handled by dsh itself and are also excluded from uninstallation scope.
  • Safety: More safe than direct pnpm up --latest; it adds backup, pinning, bundles reconciliation, dual validation, and failure rollback.
  • Power-loss recovery: If a power outage or forced termination occurs during an update or uninstallation, you can restore using the backup directory plus the node bin/dpu.mjs rollback command.
  • Uninstallation validation: After uninstallation, dsh.profile.bundles is reconciled again to assert that no residual dependency-less layers remain.

Conclusion

dsh-plugin-updater fills the safety gap caused by directly using a package manager to update plugins through a standardized operation workflow. For developers who need to frequently adjust the plugin ecosystem, it can effectively reduce the risk of environment corruption. For more details, see the GitHub repository.